@manicode@wickett This exclusionist and elitist attitude is why we have so many workforce problems in #Infosec and #tech. There are all kinds of jobs, skills and personalities that can help make the world a better place — this is also true for security.
@techspence >Client gets hit with ransomware
>I ask them if they have logs/SIEM
>Client proudly says, "We had Splunk deployed last year."
>This must be a unicorn
>Log into Splunk
>First time login screen
>Never configured. No logs.
True story
“You keep using that word “materiality”. We do not think it means what you think it means.” ~ #SEC (w/ apologies to Inigo Montoya)
#CDK hack shows SEC disclosure standards are unsettled via @CyberScoopNews @timstarks https://t.co/1N4mo03f5N
A lot of security is learning how to analyze failure, not be crippled by it, and figuring out how not to fail as hard the next time.
Be real though - it's usually a thankless job and you'll always be playing catch-up with new technologies, so high stress and lifetime learning.
@NSA_CSDirector Years ago I met a woman whose PhD dissertation examined the factors of burnout (social workers), which I found useful in infosec
Visualize a Venn diagram:
- (V) visibility of a problem / opportunity
- perceived (R) responsibility to address issue
- ability to (E) effect change
Hand motions and all😉, CISA's Jack Cable and Bob Lord are in-sync on how important the Secure by Design model is for cybersecurity. Learn more about what it means to be Secure by Design: https://t.co/n2W0UtmStQ
🔔Announcing another step toward #SecureByDesign—Through close collaboration with our partners at @Microsoft, I’m excited to announce that we’ve reached an important milestone in making logging more accessible for government & commercial entities: https://t.co/bvL2kBSL7k
I almost want to point people who are praising Microsoft for making *logs* [yes, that's right: logs] available without E5 to Chris Rock's glorious screed on wanting credit for basic things you're supposed to do. Cause it's what pops into my mind.
But I, uh, won't. 😅😅
(IYKYK)
Security FOMO no-mo! 📩Subscribe to @CISAgov's email list and you'll be the first to know about vulnerabilities, new products and services, and other security updates that impact our nation’s critical infrastructure https://t.co/fwrfrd7rsf
On this #WorldPasswordDay, I’d like to encourage everyone to read this article on safe cyber practices to learn how to keep their information and the information of their loved ones secure.
https://t.co/kgRWPn4yxi
If you are at RSAC this week and have not yet mandated phishing-resistant FIDO authentication for your organization, please spend some time looking into it. Here's one place to learn more:
https://t.co/kLbXEeb7mR
I'm honored to be speaking alongside many great folks!